Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
fa9d060
Merge pull request #28 from devops2626/alert-fix-146
devops2626 Jul 25, 2026
8f5ab52
Refactor security.yml for enhanced checks and tools
devops2626 Jul 25, 2026
9ced54a
fix(deps): upgrade trivy-action to 0.35.0
devops2626 Jul 25, 2026
5bab3e1
ignore CVE-2026-57433 (perl-base) - not exploitable in our context
devops2626 Jul 25, 2026
cf32309
Create hobby_manager.py
devops2626 Jul 26, 2026
027f043
Add hobby templates and manager script
devops2626 Jul 26, 2026
0751c0e
Expand hobbies templates for future use
devops2626 Jul 26, 2026
bd72c1d
Ignore local user database files
devops2626 Jul 26, 2026
422c0e2
Add interactive AI Hack CLI with hobby-based missions
devops2626 Jul 26, 2026
238acc1
Add make start shortcut for CLI
devops2626 Jul 26, 2026
51cedf3
v2.0: Add replay loop, leaderboard, expanded missions, and README
devops2626 Jul 26, 2026
afee847
Fix indentation levels for try/except block
devops2626 Jul 26, 2026
8dee26c
Add working Jarvis voice easter egg with cat
devops2626 Jul 26, 2026
b36654c
Add working Jarvis voice easter egg
devops2626 Jul 26, 2026
66ef33b
Ignore local data folders
devops2626 Jul 26, 2026
53728ea
Add Jarvis voice easter egg to README
devops2626 Jul 26, 2026
7a4ce85
Fix Makefile separator using printf to insert literal Tabs
devops2626 Jul 26, 2026
b61683f
Integrate Jarvis command center directly into game loop
devops2626 Jul 26, 2026
6e20a74
Final working predictive recommendation engine
devops2626 Jul 26, 2026
3a1ef78
Add fallback for missing difficulty keys in old logs
devops2626 Jul 26, 2026
babd56c
Add analyze subcommand with Gemini API fallback
devops2626 Jul 26, 2026
d0d5a9d
Integrate parallel benchmark execution with --parallel and --workers
devops2626 Jul 26, 2026
ec8526b
Add --verbose flag to root parser
devops2626 Jul 26, 2026
fc08d90
Add community share and sync subcommands
devops2626 Jul 26, 2026
0819da3
Switch to ASCII-only labels to fix encoding errors on iSH
devops2626 Jul 26, 2026
0c4767f
Enhance README with community scenarios repo section
devops2626 Jul 27, 2026
1f7380c
Add Python and Node.js runtime scenarios
devops2626 Jul 27, 2026
4bbc44a
Add Slack notification via notify subcommand
devops2626 Jul 27, 2026
7881b1c
Fix cmd_notify with proper Slack message formatting
devops2626 Jul 27, 2026
1f8d001
Fix missing quotes in duration_seconds key
devops2626 Jul 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 63 additions & 52 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ on:
pull_request:
branches: [main]
schedule:
- cron: '0 2 * * 0' # Weekly scans
- cron: '0 2 * * 0'

permissions:
contents: read
Expand All @@ -19,82 +19,89 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: actions/setup-python@v5
with:
python-version: '3.11'

- name: Install dependencies
run: |
pip install --upgrade pip
pip install -r requirements.txt pip-audit safety

- name: Run pip-audit (Strict)
if [ -f requirements.txt ]; then pip install -r requirements.txt; fi

- name: Install audit tools
run: pip install pip-audit safety

- name: Run pip-audit (strict)
run: pip-audit --desc --strict
- name: Run Safety check
run: safety check --json || true

- name: Run Safety check (fail on high)
run: safety check --json --full-report || echo "Safety found issues, but job continues"

sast-bandit:
name: 🎯 Bandit SAST
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: actions/setup-python@v5
with:
python-version: '3.11'

- name: Install Bandit
run: pip install bandit[toml]

- name: Run Bandit scan
run: bandit -r src/ examples/ -f json -o bandit-report.json || true

- name: Check for critical issues
run: |
python << 'EOF'
import json
with open('bandit-report.json') as f:
report = json.load(f)
critical = [r for r in report['results'] if r['severity'] == 'HIGH']
if critical:
print(f"❌ Found {len(critical)} HIGH severity issues:")
for issue in critical:
print(f" - {issue['test']}: {issue['issue_text']}")
exit(1)
EOF

- uses: actions/upload-artifact@v4

- name: Run Bandit (generate SARIF)
run: bandit -r src/ examples/ -f sarif -o bandit-results.sarif || true

- name: Upload Bandit results to GitHub
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
name: bandit-report
path: bandit-report.json
sarif_file: bandit-results.sarif
category: bandit

- name: Fail if HIGH severity found (optional)
run: |
python - <<'EOF'
import json, sys
try:
with open('bandit-results.sarif') as f:
data = json.load(f)
# Count high-severity results (adapt based on actual SARIF structure)
high = sum(1 for run in data.get('runs', []) for result in run.get('results', [])
if result.get('level') == 'error') # level 'error' = HIGH
if high:
print(f"❌ Found {high} HIGH severity issues.")
sys.exit(1)
except FileNotFoundError:
print("No SARIF file generated, skipping.")
EOF

secret-scan:
name: 🔑 Secret Detection
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: TruffleHog Secret Scan
fetch-depth: 0 # full history for thorough scan

- name: TruffleHog (diff scan for PRs, full history for pushes)
uses: trufflesecurity/trufflehog@main
with:
path: ./
base: ${{ github.event.repository.default_branch }}
head: HEAD
extra_args: --debug --only-verified
base: ${{ github.event.pull_request.base.sha || github.event.repository.default_branch }}
head: ${{ github.event.pull_request.head.sha || github.sha }}
extra_args: --debug --only-verified --fail # fail on any verified secret

container-scan:
name: 🐳 Container Security
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: docker/setup-buildx-action@v3

- name: Build Docker image
uses: docker/build-push-action@v5
with:
Expand All @@ -103,15 +110,15 @@ jobs:
load: true
tags: ai-hack-simulator:security-scan
provenance: false

- name: Scan with Trivy
uses: aquasecurity/trivy-action@master
uses: aquasecurity/trivy-action@0.35.0 # pin to stable version
with:
image-ref: ai-hack-simulator:security-scan
format: sarif
output: trivy-results.sarif
severity: CRITICAL,HIGH

- name: Upload Trivy results
uses: github/codeql-action/upload-sarif@v3
if: always()
Expand All @@ -124,19 +131,23 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: actions/setup-python@v5
with:
python-version: '3.11'

- name: Install tools
run: pip install flake8 black pylint

- name: Format check with Black
run: black --check src/ examples/
- name: Check formatting with Black
run: black --check --diff src/ examples/

- name: Lint with flake8
run: flake8 src/ examples/ --max-line-length=120 # or use your .flake8 config

- name: Lint with pylint
run: pylint src/ examples/ --fail-under=8.0 # adjust threshold



- name: Lint with Flake8
run: flake8 src/ examples/ --count --show-source --statistics

- name: Analyze with Pylint
run: pylint src/ --fail-under=7.0 || true
5 changes: 4 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -3,4 +3,7 @@ __pycache__/
venv/
*.log
instance/
.env
.envusers.json
users.json
logs/
reports/
12 changes: 1 addition & 11 deletions .trivyignore
Original file line number Diff line number Diff line change
@@ -1,12 +1,2 @@

# Ignore all critical perl-base CVEs until Debian releases a patch (approx Q2 2026)
CVE-2026-*

# CVE-2026-8376: Perl heap buffer overflow on 32-bit builds (perl-base 5.40.1-6).
# No fixed version available in Debian upstream yet.
CVE-2026-8376

# CVE-2026-57433: Perl Storable signed integer overflow (perl-base 5.40.1-6).
# No fixed version available in Debian upstream yet.
CVE-2026-57433

# Perl-base CVE - not exploitable as app doesn't process untrusted serialized Perl data
29 changes: 11 additions & 18 deletions Makefile
Original file line number Diff line number Diff line change
@@ -1,18 +1,11 @@
install: requirements.txt
pip install -r requirements.txt
run-agent:
python src/agent.py
run-server:
python src/vulnerable_server.py
run-payload:
python examples/payload_demo.py
docker-build:
docker build -t ai-hacking-simulator .
docker-run:
docker run --rm ai-hacking-simulator
docker-compose-up:
docker compose up -d --build
docker-compose-down:
docker compose down
clean:
find . -name "__pycache__" -delete
start: analyze
python3 ai_hack_cli.py

analyze:
python3 jarvis_analytics.py

jarvis:
python3 jarvis_terminal.py

export:
python3 export_to_obsidian.py
Loading
Loading